Published 2026-09-10 · A practical, dated checklist for small teams deploying AI in the EU.
EU AI Act Compliance Checklist for Small Teams (2026)
This is a practical engineering-and-operations checklist, not legal advice. Confirm anything material with counsel.
The EU AI Act does not switch on all at once, and that is exactly why small teams get it wrong. Your deadline depends on what your system does and which role you play — provider or deployer — not on the date the regulation was signed. Most teams we talk to cannot answer the first question an auditor asks: which articles apply to this system, and by when?
The dates that actually bind you
The phasing below follows Regulation (EU) 2026/1744 (the “Digital Omnibus”), in force from 27 July 2026, which revised several application dates.
| Obligation | Applies from | Who it hits |
|---|---|---|
| Prohibited practices (Art. 5) | 2 Feb 2025 | Everyone |
| GPAI obligations | 2 Aug 2025 | Model providers |
| Art. 50 transparency + GPAI enforcement powers | 2 Aug 2026 | Providers & deployers |
| AI-generated content marking / NCIC prohibitions | 2 Dec 2026 | Providers & deployers |
| High-risk Annex III | 2 Dec 2027 | Annex III use cases |
| Embedded in regulated products | 2 Aug 2028 | Product manufacturers |
The six-step checklist
- Inventory every AI system. Include the ones a contractor shipped, the model behind a support widget, and anything calling a third-party API. Teams routinely miss half their surface area.
- Assign a role per system. Provider (you build/place it on the market) or deployer (you use it). The obligations differ sharply, and getting this wrong misroutes everything downstream.
- Classify risk. Check Art. 5 prohibitions first, then Annex III high-risk categories, then Art. 50 transparency. A generic support chatbot is usually minimal-risk — it changes character if it screens CVs, scores credit, or does emotion inference.
- Map obligations to dates. For each applicable article, write down the binding date from the table above. This converts a vague worry into a schedule.
- Close the documentation gap. Even at minimal risk you need to be able to show why you classified it that way. A one-page rationale per system is usually enough and is what auditors ask for first.
- Re-check on a cadence. The dates moved once already. Set a recurring review, and re-verify before each milestone in the table.
Five mistakes we see repeatedly
- Using the original dates. The Digital Omnibus pushed Annex III high-risk to 2 Dec 2027. Plans built on the pre-Omnibus 2026 date are planning against a deadline that no longer exists.
- Confusing “obligation applies” with “enforcement starts”. GPAI obligations applied from 2 Aug 2025, but enforcement powers only became exercisable from 2 Aug 2026. Both dates matter; they are not the same thing.
- Assuming “we are outside the EU” means out of scope. If your system's output is used in the EU, you are likely in scope regardless of where you are incorporated.
- Treating compliance as a one-off. Adding a feature can move a system into a new risk tier. Re-classify on material change.
- Buying a “100% compliant” badge. No tool can certify that. Distrust any product that claims to.
Where tooling genuinely helps
The tedious part is not understanding the regulation — it is repeating steps 1–4 across a dozen systems and keeping them current. That is the part worth automating.
- AIActRadar classifies each system's risk tier and maps the applicable obligations to their phased deadlines with article citations, producing a risk register and a dated roadmap.
- AgentPolicy converts your written policy into checks your agents actually enforce, which matters once you have autonomous systems acting on their own.
- AgentRedTeam simulates prompt injection, tool abuse and data exfiltration against those agents, since Art. 15 robustness expectations do not stop at documentation.
All three have a free tier, so you can validate the classification on one system before committing to anything.
Frequently asked questions
- Does the EU AI Act apply to a small team outside the EU?
- It can. The Act reaches providers placing AI systems on the EU market and deployers whose systems produce output used in the EU, regardless of where the team is incorporated. If your model's output is used by people in the EU, assume you are in scope and check your role.
- When do high-risk Annex III obligations actually apply?
- Under the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), high-risk Annex III obligations apply from 2 December 2027, later than the original 2026 date.
- Is a generic support chatbot high-risk?
- Usually not. A generic customer-support chatbot is typically minimal or limited-risk. It becomes higher-risk when it is used in Annex III contexts such as employment decisions, credit scoring, or essential services, or when it does biometric or emotion-related processing.
- Do GPAI obligations apply now?
- GPAI obligations have applied since 2 August 2025, but enforcement powers for GPAI only became exercisable from 2 August 2026. Transparency obligations under Article 50 also apply from 2 August 2026.
- Do I need to watermark AI-generated content?
- Obligations covering marking and detection of AI-generated content, including the prohibition on certain subliminal or deceptive techniques (NCIC), apply from 2 December 2026.